CVE Vulnerabilities

CVE-2026-34232

Improper Handling of Syntactically Invalid Structure

Published: Apr 17, 2026 | Modified: Apr 27, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a server crash when one is encountered in the status vector. An unauthenticated attacker can exploit this by sending a crafted op_response packet to the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

Weakness

The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.

Affected Software

NameVendorStart VersionEnd Version
FirebirdFirebirdsql3.0.0 (including)3.0.14 (excluding)
FirebirdFirebirdsql4.0.0 (including)4.0.7 (excluding)
FirebirdFirebirdsql5.0.0 (including)5.0.4 (excluding)
Firebird3.0Ubuntuupstream*
Firebird4.0Ubuntuupstream*

References